
GIAC Red Team Professional
Domain 3Objective 1
Attacking Active Directory GRTP Practice Questions (Page 2)
Part of the Active Directory Attacks and Post-Exploitation domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
19concepts
Questions 6–10
- 6
You have compromised a domain admin account and want to maintain persistence even if the domain admin password is changed. You also want to avoid detection by the security team that monitors changes to privileged groups. Which technique should you use?
Select an answer first - 7
You have compromised a user account that has 'GenericAll' permission on a group that contains domain admins. You need to gain domain admin privileges. Which technique should you use?
Select an answer first - 8
What is the main difference between unconstrained and constrained delegation?
Select an answer first - 9
Which process on a domain controller is typically targeted in a skeleton key attack?
Select an answer first - 10
You have gained administrative access to a domain controller. You want to maintain access to the domain by allowing any user to authenticate with a single password, but you need to avoid leaving a persistent file on disk that could be detected by antivirus. Which technique should you use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.